Blob Blame History Raw
diff -urp suricata-4.1.5.orig/etc/suricata.service.in suricata-4.1.5/etc/suricata.service.in
--- suricata-4.1.5.orig/etc/suricata.service.in	2019-09-25 17:41:26.689250441 -0400
+++ suricata-4.1.5/etc/suricata.service.in	2019-09-25 17:41:58.386247040 -0400
@@ -13,5 +13,11 @@ ExecStartPre=/bin/rm -f @e_rundir@surica
 ExecStart=/sbin/suricata -c @e_sysconfdir@suricata.yaml --pidfile @e_rundir@suricata.pid $OPTIONS
 ExecReload=/bin/kill -USR2 $MAINPID
 
+### Security Settings ###
+MemoryDenyWriteExecute=true
+LockPersonality=true
+ProtectControlGroups=true
+ProtectKernelModules=true
+
 [Install]
 WantedBy=multi-user.target